Executive brief
Microsoft Office SharePoint, a widely used collaboration and document management platform, is affected by a security vulnerability that could allow an attacker to perform spoofing. An authorized user could exploit this flaw to execute malicious scripts in another user's browser session. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive information within the SharePoint environment.
Technical details
A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation (CWE-79). An authenticated attacker with low privileges can exploit this vulnerability over the network, though it requires interaction from a victim (User Interaction: Required). Successful exploitation allows the attacker to perform spoofing and execute arbitrary script in the context of the victim's browser. The vulnerability has a CVSS 3.1 base score of 4.6, reflecting limited impacts on confidentiality and integrity. Patch information is typically available via the Microsoft Security Update Guide.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory